A new research study highlights a particularly complex risk for cloud environments, revealing that a remote Spectre could leak data from Cloudflare Workers. The researchers were able to extract a JSON Web Token (JWT) from a co-located Worker, reaching a rate of up to 12 bits per second.

This performance is impressively higher than that of a previous attack in 2021, when the leak rate reached just 2 bits per minute. The researchers emphasize, however, that the experiment was conducted in a controlled environment and no access to real customer data was detected.
How the attack works
The experiment used two Workers, one controlled by the alleged attacker and one victim Worker. The JWT was intentionally placed in the memory of the second one, to test whether it could be retrieved by the first one via side channels.
See also: Cloudflare: New announcements on Hugging Face, Workers AI and new products
Cloudflare Workers is based on V8 isolates , or isolated JavaScript execution environments , allowing code from different clients to run within the same process. This approach reduces startup latency and improves cloud efficiency, but it introduces a different type of risk than fully isolating separate processes.
Spectre attacks exploit features of synchronous instruction execution on processors and can reveal information through very small differences in execution times. In this case, the researchers sought a way to turn these small differences into a remote data leakage channel.
The problem with WebSockets
One of the most important findings concerns WebSockets. Although Workers limits the accuracy of local timing mechanisms, the researchers found that WebSocket communications could act as a remote source of time measurements.
At the same time, Durable Objects could keep a Worker process active for many hours. Under certain conditions, the prolonged execution continued before the DyPrIs isolation mechanism was activated .
The researchers also found that heavy I/O activity over WebSocket affected the iTLB cache and could limit the signal that DyPrIs used to detect suspicious behavior. Simply put, the communication activity itself could make the attack harder to detect.

The difference in Cloudflare and researchers' estimates
Cloudflare has addressed the issue as a limitation in its implementation of DyPrIs, while researchers argue that the findings reveal deeper limitations of the specific detection method.
According to the study, protection should operate during execution and be based on signals that cannot be easily influenced by other system activities.
See also: Cloudflare CDN flaw leaks user location data
The tests were conducted on Linux servers with AMD EPYC Zen 2 and Zen 3 processors. The best performance was recorded when CPU utilization was relatively low, around 10% to 25%. Even when the load increased, however, the attack remained feasible, although the leak rate decreased.
360 times faster leakage
The study recorded a maximum rate of 12 bits per second, with 99.16% accuracy. This is a significant improvement over the 2 bits per minute of the previous attack, dramatically increasing the practical effectiveness of such a side-channel.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The development is particularly significant because in 2021, Cloudflare and TU Graz demonstrated a Spectre attack against Workers at a rate of about 120 bits per hour and proposed DyPrIs as a defense mechanism. The new research shows that countering such attacks requires constant reassessment, as side-channel techniques evolve alongside protection measures.
The new protection measures
Cloudflare has already taken steps to strengthen the security of Workers. Measures include an improved DyPrIs, V8 Sandbox, and memory isolation via Memory Protection Keys (MPK).

MPK uses hardware-enforced protection keys for Worker memory regions. Combined with V8 Sandbox and a dynamically swappable memory layout, the goal is to prevent neighboring sandboxes from sharing the same key.
See also: Cloudflare Kitesurf: A Browser Built for AI Agents — What's Changing
Cloudflare estimated that random MPK assignment could detect about 92% of cross-isolate accesses. The swapping memory layout was designed to fill the remaining gap.
The company states that the vulnerability has now been addressed in production and that there is no evidence of active exploitation in the last three years. However, the research reminds us that in cloud environments, strong isolation is not a one-time solution, but an ongoing process of adaptation to increasingly sophisticated attacks.
